Facebook Twitter Instagram
    • Privacy Policy
    • Contact Us
    Facebook Twitter Instagram Pinterest Vimeo
    AI Home SecurityAI Home Security
    • Home
    • Home Security
    • Cyber Security
    • Biometric Technology
    Contact
    AI Home SecurityAI Home Security
    Cyber Security

    Luna Grabber Malware Targets Roblox Gaming Devs

    justmattgBy justmattgAugust 27, 2023No Comments2 Mins Read

    [ad_1]

    Since the start of this month, researchers at ReversingLabs have found a host of malicious, multistage packages on the npm public repository that implant an open source, information-stealing malware known as Luna Grabber.

    To infect its victims, the packages imitate a legitimate package, such as noblox.js — “a Node.js Roblox API wrapper used to write scripts that interact with the Roblox gaming platform,” according to a ReversingLabs analysis on the campaign. The malicious packages reproduce code from the legitimate package but add information-stealing functions to the mix. 

    Developers of the scripts that ultimately run on the Roblox platform could thus unwittingly fall prey to Luna Grabber, which is an “open-source malware designed to steal information from the user’s local web browser, Discord application, and more,” according to ReversingLabs.

    The researchers first came upon these types of campaigns while monitoring the npm public repository, and noblox.js-vps was the first malicious package they happened upon. The package displayed suspicious behaviors, such as executing commands in the command line, containing URLs that linked to Discord attachments, enumerating files in a given directory, and enumerating user information, among other actions. Since then, ReversingLabs researchers have also identified other malicious packages that are similar, such as noblox.js-ssh and noblox.js-secure.

    “Even though the impact of noblox.js-vps and other malicious packages in this campaign wasn’t high, it is a reminder to security and software development teams that threats lurk consistently in open-source repositories, making choosing which package to include in the development process critical,” wrote the researchers. 

    Keep up with the latest cybersecurity threats, newly-discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

    Subscribe

    [ad_2]

    Source link

    Previous ArticleEmployee Falls Victim to SIM Swapping Attack
    Next Article Learn How Your Business Data Can Amplify Your AI/ML Threat Detection Capabilities
    justmattg
    • Website

    Related Posts

    Cyber Security

    Name That Toon: Last Line of Defense

    April 16, 2024
    Cyber Security

    OpenJS Foundation Targeted in Potential JavaScript Project Takeover Attempt

    April 16, 2024
    Cyber Security

    Middle East Cyber Ops Intensify, With Israel the Main Target

    April 16, 2024
    Add A Comment

    Leave A Reply Cancel Reply

    Facebook Twitter Instagram Pinterest
    • Privacy Policy
    • Contact Us
    AI Home Security © 2025 All rights reserved | Designed By ESmartsSolution

    Type above and press Enter to search. Press Esc to cancel.

    ↑